Zoom Unveils Four-Phase End-to-End Encryption Plan for Enhanced Security
Zoom publishes a draft design for end-to-end encryption on GitHub, aiming to protect users from outsiders and insiders through a structured four-phase approach.
Zoom releases a draft design for its end-to-end encryption offering as part of a major security and privacy upgrade. The video conferencing platform publishes this draft on GitHub for peer review, outlining a structured implementation plan developed with input from clients, cryptography experts, and civil society. This initiative aims to protect users from malicious outsiders, participants, and insiders by ensuring confidentiality, integrity, and abuse prevention.
The demand for stronger security grows as global Zoom usage skyrockets during the COVID-19 pandemic. Increased scrutiny reveals that Zoom does not actually offer true end-to-end encryption despite previous claims, prompting the company to apologize for the confusion and launch a 90-day security improvement plan. As part of this rapid response, Zoom implements AES 256-bit GCM encryption for data in transit and acquires the secure messaging service Keybase.
Keybase co-founder Max Krohn now leads Zoom's security engineering team and helps develop the new four-phase encryption roadmap. The first phase upgrades the meeting key exchange protocol to use public-key cryptography so that keys remain secret from the server. The subsequent three phases focus on hardening user identity verification to maintain server honesty during key exchanges and to provide meeting hosts with better tools for managing participant access.